Privacy Policy
This Privacy Policy applies to all users and visitors of our digital offerings.
Preamble
With the following Privacy Policy, we would like to inform you about the types of your personal data (hereinafter also referred to simply as "data") we process, for what purposes, and to what extent. This Privacy Policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications, as well as within external online presences, such as our social media profiles (hereinafter collectively referred to as "Online Offering").
The terms used are not gender-specific.
Last updated: June 26, 2026
Data Controller
Dominik Hettich
c/o COCENTER, Koppoldstr. 1, 86551 Aichach, Germany
info@playmunity.com
Data Collection when Downloading the App
When downloading our app from the Apple App Store or the Google Play Store, the necessary information is transferred to the operator of the respective app store (in particular, username, email address, account customer number, time of download, and individual device identification number). We have no influence over this data collection and are not responsible for it. We process this provided data only to the extent necessary for downloading the app to your smartphone.
Types of Processed Data
- Master data (e.g., name, date of birth, gender, address)
- Contact data (e.g., email address)
- Access data (e.g., login, password hash, authentication data)
- Contract data (e.g., booked services, subscription terms)
- Payment and billing data (e.g., invoice information, Stripe)
- Communication content (e.g., chat messages, support requests)
- Usage data (e.g., visited pages, app functions, interactions)
- Connection data (e.g., IP address, device type, operating system, app version)
- Push notification data (e.g., tokens for Apple/Google Push)
- Address book data (only with consent and if necessary for functionality)
- Consent data (e.g., timestamp, source, withdrawal)
- Login/usage history
- Newsletter data (e.g., open and click rates)
Processing only takes place to the extent necessary for the provision of our services or based on legal obligations.
Purposes of Data Processing
- Provision of free and paid services and functions
- Community, communication, and account services
- Registration, planning, and execution of training sessions
- Billing and invoicing
- Registration and planning of teams, team and club events
- Organization and administration of club and team memberships
- Personalization of the user experience
- Optimization and further development of technical functions
- Web analytics and reach measurement
- Affiliate tracking
- Security, fraud prevention, and compliance with terms of use
Legal Bases
- Consent (Art. 6 (1) (a) GDPR)
- Performance of a contract (Art. 6 (1) (b) GDPR)
- Legal obligation (Art. 6 (1) (c) GDPR)
- Legitimate interest (Art. 6 (1) (f) GDPR)
Transmission of Data to Third Parties
Personal data is only shared if legally permitted, contractually necessary, or technically required. We have concluded corresponding Data Processing Agreements (DPA) according to Art. 28 GDPR with our IT service providers and hosting providers.
- Training schools, freelance and employed coaches, as well as their co-coaches and designated representatives
- Club boards and other club organs (e.g., youth warden or team captain)
- IT service providers
- Hosting providers (e.g., All-Inkl.com)
- Payment services (e.g., Stripe)
- Authorities in the event of a legal obligation
The training, course, or event offers are organized and conducted by independent third-party providers (e.g., coaches, clubs, or similar partners). For the registration, organization, and execution of the booking, your personal data will be forwarded to the respective third-party provider(s), who process the data for the execution of the training. This is necessary to organize your registration, conduct the training, and manage club or team memberships. The recipients only receive the information required in the respective context.
Data Transfers to Third Countries
If data is transferred to third countries (e.g., the USA), this only takes place if appropriate safeguards are in place:
- EU adequacy decisions (e.g., EU-U.S. Data Privacy Framework)
- Standard Contractual Clauses (SCCs) of the EU Commission
- Other appropriate safeguards
Retention and Deletion
Storage only occurs for as long as necessary to fulfill contracts or legal obligations:
- 10 years – tax documents (§ 147 AO)
- 6 years – business correspondence (§ 257 HGB)
- 3 years – civil law claims (§§ 195, 199 BGB)
Security Measures
We implement appropriate technical and organizational measures in accordance with Art. 32 GDPR. This includes, among other things, SSL/TLS encryption for secure data transmission.
Rights of Data Subjects
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7 (3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise your rights, a message to info@playmunity.com is sufficient.
Automated decision-making, including profiling, does not take place.
Further Information on Data Processing
Registration, form usage, app interactions, as well as technical information (e.g., IP, device, browser data) are processed in compliance with data protection regulations. Access to device functions such as contacts only occurs with your prior consent and in accordance with your system settings.
Pseudonymous use is not possible, as certain functions and services require unambiguous identification.
To enable the community functions of the platform (e.g., within the context of teams and clubs), certain profile information is generically visible to other registered users across the entire platform. By default, this includes your first and last name, your profile picture, as well as other voluntary details such as your year of birth, club affiliations, and playing strength. Furthermore, you have the option to make your profile completely public. In this case, selected profile data may also be visible to unregistered third parties, for example via publicly accessible profile pages or search engine indexing. You can control the visibility of your profile and individual information at any time in your account settings.
Access Rights for Club Managers: If you join a club via the platform and add it to your profile, the authorized club managers of this club are granted access to view your email address. This access is strictly tied to your club membership and serves exclusively the purpose of member verification and organizational communication.
Voluntary Exchange of Contact Details upon Match Agreement
If you arrange a specific match with another user, you can optionally share your email address and/or phone number with them to simplify communication. This data sharing is done individually per match, is based on your voluntary consent (Art. 6 (1) (a) GDPR), and is exclusively visible to the respectively confirmed playing partner.
Use of Firebase (Google)
For our mobile app and web applications, we use Firebase, a development platform provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google"). Firebase supports us with various background functions and real-time data processing.
Firebase Cloud Messaging (Push Notifications)
To actively inform you about news, events, or appointments in the community, we use the Firebase Cloud Messaging service for our apps. If you explicitly allow the receipt of push notifications on your device (iOS/Android) or in the browser, an anonymous identification token is generated. This token is stored on our servers as well as by Google and serves exclusively for the secure technical delivery of notifications to your device. Google cannot draw conclusions about your direct identity (e.g., your name) from this. The legal basis for this service is your explicit consent (Art. 6 (1) (a) GDPR). You can revoke this consent at any time via your device's system settings by deactivating notifications for our app.
Firebase Realtime Database (Live Ticker & Scoring)
To provide real-time functions, such as the live ticker and immediate updates of match scores, we use the Firebase Realtime Database. This synchronizes data without delay between users' devices. To protect your data, we have configured this service so that the storage and processing of database content take place exclusively on servers within the European Union (EU). The processing is based on our legitimate interest in delivering performant and modern live content (Art. 6 (1) (f) GDPR).
If, in exceptional cases, technical metadata is transferred by Google to third countries (e.g., the USA) within the scope of using Firebase services, this is done on the basis of the EU-U.S. Data Privacy Framework (adequacy decision) and through the conclusion of Standard Contractual Clauses of the EU Commission.
Use of the Mobile App (Capacitor WebView)
Our mobile applications for iOS and Android are based on the "Capacitor" framework. Technically, this acts as a so-called "Live URL Wrapper" (WebView). This means that the app essentially loads our secured live website directly and displays it on your mobile device.
Data Processing Analogous to the Website: Due to this architecture, data processing within the app is identical to using our website via a regular browser. The mechanisms described in this Privacy Policy, such as the storage of server log files and the use of Web Storage (Local Storage), also apply within the app.
Device Functions and Permissions: The Capacitor app acts as a bridge between the loaded website and the native functions of your smartphone. If functions are to be used that access deeper device interfaces (such as receiving push notifications), the operating system (iOS or Android) strictly asks you in advance for your explicit permission via a system dialog. Without your active consent, no access to these native functions occurs.
Technical App Protocols: For internal data traffic between the app and interfaces (e.g., for authentication with Firebase), Capacitor uses specific local requests (such as capacitor://localhost or http://localhost). These serve exclusively for the secure assignment and technical authorization of app requests to the servers and do not transmit any additional personal data.
Notifications, Newsletters & Cookies
Only technically necessary cookies are used, which are required for the operation and functionality of our website. Therefore, a cookie consent tool is not necessary.
Email Notifications for Matchmaking Events
In addition to or as an alternative to push notifications, we offer you the option to be informed by email about certain events within the app (e.g., new match requests or match confirmations). Since you use these notifications optionally and can customize them individually in your account settings, the dispatch is based on your voluntary consent (Art. 6 (1) (a) GDPR). You can manage these settings yourself at any time and completely or partially deactivate the receipt of emails.
Newsletter
In addition, we offer a newsletter. The use of this service is based on your voluntary consent according to Art. 6 (1) (a) GDPR. You can revoke your consent at any time with effect for the future (e.g., by unsubscribing from the newsletter).
Links to Third-Party Websites (Affiliate Links)
On our website, you will find recommendations for products or services in some places, which are marked with an asterisk (*) or as an advertisement. When you click on such a so-called affiliate link, you will be redirected either directly or via a partner network to the website of the respective third-party provider. These are external websites over whose content and privacy practices we have no influence. If you make a transaction there (e.g., a purchase or a booking), we may be credited with a commission for this.
Scope of Data Processing
If you follow an affiliate link, cookies or similar technologies may be placed on your device by the respective partner network or provider as part of affiliate tracking. These serve to trace the origin of transactions (conversions). The cookies set in this process do not contain directly personally identifiable data, but generally only an anonymous identification number (affiliate ID) and a reference ID of the respective visitor.
In addition, information such as the referring page, the time of the click, the destination page of the redirection, and an online identifier of the user may be processed. Please note that the respective providers' websites have their own privacy and cookie policies, over the content of which we have no influence.
Within the scope of our own evaluation, we solely collect and store in an anonymized form:
- Referring website,
- Time of the click,
- Destination page of the redirection,
- Online identifier without direct personal reference.
Legal Basis and Purpose of Data Processing
The processing of data in connection with affiliate links is based on our legitimate interest as well as the legitimate interest of the participating providers and networks in proper commission billing and fraud prevention (Art. 6 (1) (f) GDPR). The storage of the data serves in particular for billing, statistical evaluation, and the traceability of transactions for tax and billing purposes.
Right to Object
You can prevent the storage of cookies set by affiliate networks at any time via your browser settings or delete already stored cookies. Depending on the browser used, different setting options are available for this.
For requests for information, rectification, or deletion regarding your personal data, you can contact the address mentioned in this Privacy Policy at any time.
Data Collection on This Website
Server Log Files
Our hosting provider automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version,
- Operating system used,
- Referrer URL,
- Hostname of the accessing computer,
- Time of the server request,
- IP address.
This data is not merged with other data sources. The collection of this data is based on Art. 6 (1) (f) GDPR. We have a legitimate interest in the technically error-free presentation, as well as the stability and security of our website.
Inquiries via Email or Telephone
If you contact us via email or telephone, the personal data you transmit (e.g., name, contact details, content of the inquiry) will be stored and processed for the purpose of handling your request. This data will not be passed on to third parties without your consent.
The processing is based on Art. 6 (1) (b) GDPR if your inquiry is related to the fulfillment of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the efficient processing of incoming inquiries (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) if this has been obtained.
The data transmitted by you will be deleted as soon as the purpose for storing it no longer applies and no statutory retention obligations prevent it.
Web Storage (Local Storage)
This website uses web storage technology (e.g., "Local Storage") to store certain application data locally in the browser of your end device, provided your browser supports this technology and JavaScript is activated. The goal is to make the use of our website technically more stable and user-friendly.
You can remove entries in the local storage at any time by deleting your browser history. You can also restrict or deactivate the use of web storage via your browser settings; in this case, however, the functionality of our website may be limited.
Changes to this Policy
This Privacy Policy may be updated in the event of legal changes. Please check back regularly. We will highlight significant changes.
Version 3 – As of: 26.06.2026